Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 7.9

Security of Assets Off-Premises: A Practical Implementation Guide

Protect organizational assets whenever they leave controlled premises.

This control concerns protecting off-premises assets while traveling, at home, with third parties or in temporary locations.

Practical interpretation: Protection should address custody, transport, storage, environmental conditions, theft, observation, connectivity and rapid incident reporting.

What should the control achieve?

  • Off-premises use is authorized according to risk.
  • Custody and location are traceable where necessary.
  • Devices and information receive suitable technical and physical safeguards.
  • Loss, damage and border or travel risks are managed.

Step-by-step implementation

1

Define off-premises scenarios

Cover remote work, travel, customer sites, repair, storage and courier transport.

2

Set authorization and custody

Record asset holder, purpose, location, duration and responsibilities.

3

Apply protection baseline

Use encryption, screen lock, minimal local data, secure cases and remote disablement.

4

Provide travel rules

Address vehicles, hotels, airports, borders, high-risk countries and public discussion.

5

Control third-party handling

Use approved repairers, couriers, contracts and chain of custody.

6

Respond and reconcile

Report loss promptly, revoke access and confirm return or disposition.

What this could look like in practice

Consultants traveling internationally use managed encrypted laptops with minimal local data. Devices remain carry-on, are not left in vehicles and high-risk destinations require a loan device that is wiped after return.

ActivityPractical implementationEvidence
Home workAsset is stored securely and household access is prevented.User acknowledgement
TravelRisk tier determines device and connectivity safeguards.Travel approval
RepairApproved provider receives device under tracked custody.Repair record
LossSessions are revoked and remote wipe considered.Incident ticket

Implementation evidence

  • Off-premises policy
  • Asset assignments
  • Travel risk assessments
  • Device baseline
  • Courier or repair records
  • Loss reports
  • Remote actions
  • Return reconciliation

Useful metrics

  • Off-premises losses
  • Lost assets reported within target
  • Travel exceptions
  • Assets not reconciled

Common mistakes

  • Leaving devices in vehicles.
  • Assuming encryption addresses physical loss completely.
  • Using unknown repair shops.
  • Crossing borders without assessing inspection risk.
  • Keeping sensitive local copies unnecessarily.

Questions an auditor may ask

  • Which assets may leave premises?
  • How are high-risk travel scenarios handled?
  • Show third-party custody evidence.
  • What happens after loss?
Implementation test: Walk through a realistic trip from packing to return and verify custody, storage, connectivity, border, incident and wipe controls.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.